<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic change data upon indexing Admin-0, Admin-1, Admin-2 --&amp;gt; Admin in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/change-data-upon-indexing-Admin-0-Admin-1-Admin-2-gt-Admin/m-p/457891#M79143</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I'm reading data from a JMeter test. One field is either named Admin or Admin-0, Admin-1 or Admin-2. The field is named ACL&lt;/P&gt;

&lt;P&gt;I want Splunk to index this only as Admin. As written above, there is a value Admin which should be kept but the others should be renamed to Admin (instead of Admin-0 etc.).&lt;/P&gt;

&lt;P&gt;My props.conf already looks like this&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[mySourceType]
REPORT-jmeter = REPORT-jmeter
EXTRACT-full = ^(?&amp;lt;timeStamp&amp;gt;[^,]*),(?&amp;lt;elapsed&amp;gt;[^,]*),**"(?&amp;lt;label&amp;gt;[^,]*),(?&amp;lt;ACL&amp;gt;[^"]*)"**,(?&amp;lt;responseCode&amp;gt;[^,]*),(?&amp;lt;responseMessage&amp;gt;[^,]*),(?:(?&amp;lt;targetHost&amp;gt;[^\s]*)\s(?&amp;lt;JMeterThread&amp;gt;[^,]*))?,(?&amp;lt;dataType&amp;gt;[^,]*),(?&amp;lt;success&amp;gt;[^,]*),(?&amp;lt;failureMessage&amp;gt;[^,]*),(?&amp;lt;bytes&amp;gt;[^,]*),(?&amp;lt;sentBytes&amp;gt;[^,]*),(?&amp;lt;grpThreads&amp;gt;[^,]*),(?&amp;lt;allThreads&amp;gt;[^,]*),(?&amp;lt;URL&amp;gt;[^,]*),(?&amp;lt;Latency&amp;gt;[^,]*),(?&amp;lt;IdleTime&amp;gt;[^,]*),(?&amp;lt;Connect&amp;gt;[^$]*)
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Example data:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;2019/08/21 14:52:14.222,2003**,"Upload Document TXT, User-0"**,302,OK,hostname 1-1,text,true,,1234,0,1,1,https://FQDN,2003,0,0
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;So the above props.conf already splits two strings into two fields.&lt;/P&gt;

&lt;P&gt;May I ask someone to help me to achieve this?&lt;/P&gt;

&lt;P&gt;Thanks in advance!&lt;/P&gt;</description>
    <pubDate>Wed, 21 Aug 2019 12:59:48 GMT</pubDate>
    <dc:creator>mhornste</dc:creator>
    <dc:date>2019-08-21T12:59:48Z</dc:date>
    <item>
      <title>change data upon indexing Admin-0, Admin-1, Admin-2 --&gt; Admin</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/change-data-upon-indexing-Admin-0-Admin-1-Admin-2-gt-Admin/m-p/457891#M79143</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I'm reading data from a JMeter test. One field is either named Admin or Admin-0, Admin-1 or Admin-2. The field is named ACL&lt;/P&gt;

&lt;P&gt;I want Splunk to index this only as Admin. As written above, there is a value Admin which should be kept but the others should be renamed to Admin (instead of Admin-0 etc.).&lt;/P&gt;

&lt;P&gt;My props.conf already looks like this&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[mySourceType]
REPORT-jmeter = REPORT-jmeter
EXTRACT-full = ^(?&amp;lt;timeStamp&amp;gt;[^,]*),(?&amp;lt;elapsed&amp;gt;[^,]*),**"(?&amp;lt;label&amp;gt;[^,]*),(?&amp;lt;ACL&amp;gt;[^"]*)"**,(?&amp;lt;responseCode&amp;gt;[^,]*),(?&amp;lt;responseMessage&amp;gt;[^,]*),(?:(?&amp;lt;targetHost&amp;gt;[^\s]*)\s(?&amp;lt;JMeterThread&amp;gt;[^,]*))?,(?&amp;lt;dataType&amp;gt;[^,]*),(?&amp;lt;success&amp;gt;[^,]*),(?&amp;lt;failureMessage&amp;gt;[^,]*),(?&amp;lt;bytes&amp;gt;[^,]*),(?&amp;lt;sentBytes&amp;gt;[^,]*),(?&amp;lt;grpThreads&amp;gt;[^,]*),(?&amp;lt;allThreads&amp;gt;[^,]*),(?&amp;lt;URL&amp;gt;[^,]*),(?&amp;lt;Latency&amp;gt;[^,]*),(?&amp;lt;IdleTime&amp;gt;[^,]*),(?&amp;lt;Connect&amp;gt;[^$]*)
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Example data:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;2019/08/21 14:52:14.222,2003**,"Upload Document TXT, User-0"**,302,OK,hostname 1-1,text,true,,1234,0,1,1,https://FQDN,2003,0,0
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;So the above props.conf already splits two strings into two fields.&lt;/P&gt;

&lt;P&gt;May I ask someone to help me to achieve this?&lt;/P&gt;

&lt;P&gt;Thanks in advance!&lt;/P&gt;</description>
      <pubDate>Wed, 21 Aug 2019 12:59:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/change-data-upon-indexing-Admin-0-Admin-1-Admin-2-gt-Admin/m-p/457891#M79143</guid>
      <dc:creator>mhornste</dc:creator>
      <dc:date>2019-08-21T12:59:48Z</dc:date>
    </item>
    <item>
      <title>Re: change data upon indexing Admin-0, Admin-1, Admin-2 --&gt; Admin</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/change-data-upon-indexing-Admin-0-Admin-1-Admin-2-gt-Admin/m-p/457892#M79144</link>
      <description>&lt;P&gt;marking the interesting lines bold did not work&lt;/P&gt;

&lt;P&gt;"(?[^,]&lt;EM&gt;),(?[^"]&lt;/EM&gt;)"&lt;/P&gt;

&lt;P&gt;the above regex splits the two values already into two fields. ACL should have only Admin or User (without -0 etc.)&lt;/P&gt;</description>
      <pubDate>Wed, 21 Aug 2019 13:37:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/change-data-upon-indexing-Admin-0-Admin-1-Admin-2-gt-Admin/m-p/457892#M79144</guid>
      <dc:creator>mhornste</dc:creator>
      <dc:date>2019-08-21T13:37:18Z</dc:date>
    </item>
    <item>
      <title>Re: change data upon indexing Admin-0, Admin-1, Admin-2 --&gt; Admin</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/change-data-upon-indexing-Admin-0-Admin-1-Admin-2-gt-Admin/m-p/457893#M79145</link>
      <description>&lt;P&gt;Try this&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;EXTRACT-full = ^(?&amp;lt;timeStamp&amp;gt;[^,]*),(?&amp;lt;elapsed&amp;gt;[^,]*),"(?&amp;lt;label&amp;gt;[^,]*),(?&amp;lt;ACL&amp;gt;[^-"]*)(-\d+)*",(?&amp;lt;responseCode&amp;gt;[^,]*),(?&amp;lt;responseMessage&amp;gt;[^,]*),(?:(?&amp;lt;targetHost&amp;gt;[^\s]*)\s(?&amp;lt;JMeterThread&amp;gt;[^,]*))?,(?&amp;lt;dataType&amp;gt;[^,]*),(?&amp;lt;success&amp;gt;[^,]*),(?&amp;lt;failureMessage&amp;gt;[^,]*),(?&amp;lt;bytes&amp;gt;[^,]*),(?&amp;lt;sentBytes&amp;gt;[^,]*),(?&amp;lt;grpThreads&amp;gt;[^,]*),(?&amp;lt;allThreads&amp;gt;[^,]*),(?&amp;lt;URL&amp;gt;[^,]*),(?&amp;lt;Latency&amp;gt;[^,]*),(?&amp;lt;IdleTime&amp;gt;[^,]*),(?&amp;lt;Connect&amp;gt;[^$]*)
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 21 Aug 2019 13:48:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/change-data-upon-indexing-Admin-0-Admin-1-Admin-2-gt-Admin/m-p/457893#M79145</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2019-08-21T13:48:47Z</dc:date>
    </item>
    <item>
      <title>Re: change data upon indexing Admin-0, Admin-1, Admin-2 --&gt; Admin</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/change-data-upon-indexing-Admin-0-Admin-1-Admin-2-gt-Admin/m-p/457894#M79146</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;thanks, that worked! There is one small issue left: the label field sometimes still has the ACL (Admin/ User) left. See result of the new indexed data below:&lt;/P&gt;

&lt;P&gt;&lt;A href="https://imgur.com/a/pktkt3s"&gt;Screenshot result&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Aug 2019 14:10:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/change-data-upon-indexing-Admin-0-Admin-1-Admin-2-gt-Admin/m-p/457894#M79146</guid>
      <dc:creator>mhornste</dc:creator>
      <dc:date>2019-08-21T14:10:36Z</dc:date>
    </item>
    <item>
      <title>Re: change data upon indexing Admin-0, Admin-1, Admin-2 --&gt; Admin</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/change-data-upon-indexing-Admin-0-Admin-1-Admin-2-gt-Admin/m-p/457895#M79147</link>
      <description>&lt;P&gt;&lt;A href="https://imgur.com/a/pktkt3s"&gt;https://imgur.com/a/pktkt3s&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Aug 2019 14:21:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/change-data-upon-indexing-Admin-0-Admin-1-Admin-2-gt-Admin/m-p/457895#M79147</guid>
      <dc:creator>mhornste</dc:creator>
      <dc:date>2019-08-21T14:21:01Z</dc:date>
    </item>
    <item>
      <title>Re: change data upon indexing Admin-0, Admin-1, Admin-2 --&gt; Admin</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/change-data-upon-indexing-Admin-0-Admin-1-Admin-2-gt-Admin/m-p/457896#M79148</link>
      <description>&lt;P&gt;Try this&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;EXTRACT-full = ^(?&amp;lt;timeStamp&amp;gt;[^,]*),(?&amp;lt;elapsed&amp;gt;[^,]*),"(?&amp;lt;label&amp;gt;[^,]+),(?&amp;lt;ACL&amp;gt;[^-"]+)(-\d*)*",(?&amp;lt;responseCode&amp;gt;[^,]*),(?&amp;lt;responseMessage&amp;gt;[^,]*),(?:(?&amp;lt;targetHost&amp;gt;[^\s]*)\s(?&amp;lt;JMeterThread&amp;gt;[^,]*))?,(?&amp;lt;dataType&amp;gt;[^,]*),(?&amp;lt;success&amp;gt;[^,]*),(?&amp;lt;failureMessage&amp;gt;[^,]*),(?&amp;lt;bytes&amp;gt;[^,]*),(?&amp;lt;sentBytes&amp;gt;[^,]*),(?&amp;lt;grpThreads&amp;gt;[^,]*),(?&amp;lt;allThreads&amp;gt;[^,]*),(?&amp;lt;URL&amp;gt;[^,]*),(?&amp;lt;Latency&amp;gt;[^,]*),(?&amp;lt;IdleTime&amp;gt;[^,]*),(?&amp;lt;Connect&amp;gt;[^$]*)
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 21 Aug 2019 15:25:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/change-data-upon-indexing-Admin-0-Admin-1-Admin-2-gt-Admin/m-p/457896#M79148</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2019-08-21T15:25:37Z</dc:date>
    </item>
    <item>
      <title>Re: change data upon indexing Admin-0, Admin-1, Admin-2 --&gt; Admin</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/change-data-upon-indexing-Admin-0-Admin-1-Admin-2-gt-Admin/m-p/457897#M79149</link>
      <description>&lt;P&gt;That worked, thanks so much!&lt;/P&gt;</description>
      <pubDate>Thu, 22 Aug 2019 07:34:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/change-data-upon-indexing-Admin-0-Admin-1-Admin-2-gt-Admin/m-p/457897#M79149</guid>
      <dc:creator>mhornste</dc:creator>
      <dc:date>2019-08-22T07:34:54Z</dc:date>
    </item>
  </channel>
</rss>

